Description
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation.

This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an IDOR (Insecure Direct Object Reference) in Adam Retail Automation Ltd.'s MobilMen 20T that allows an authenticated user to manipulate a user‑controlled key, bypassing the software’s authorization checks and granting privilege escalation. The flaw is classified as CWE‑639, where improper verification of a user‑supplied key permits operations that should be restricted.

Affected Systems

Affected products include Adam Retail Automation Ltd.'s MobilMen 20T, specifically versions from v3 up through 10072026. Users running any of these builds must verify whether they are within this range to determine if the system is vulnerable.

Risk and Exploitability

This issue carries a CVSS score of 8.8, indicating high severity, and an EPSS score of < 1%, indicating a very low but non‑zero exploitation probability. It is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker would need a valid authenticated session; the vulnerability allows an authenticated user to manipulate a key, so the likely attack vector involves exploitation over the network by manipulating legitimate user session data.

Generated by OpenCVE AI on July 29, 2026 at 10:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MobilMen 20T to a version newer than 10072026 if one is available; consult the vendor’s release notes for confirmation.
  • Restrict use of user‑controlled keys by enforcing role‑based access control, allowing only privileged personnel to perform key‑related operations.
  • Enable detailed auditing and continuously monitor logs for signs of unauthorized privilege escalation or anomalous key usage.

Generated by OpenCVE AI on July 29, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adam Retail Automation
Adam Retail Automation mobilmen 20t
Vendors & Products Adam Retail Automation
Adam Retail Automation mobilmen 20t

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title IDOR in AdamPOS' MobilMen 20T
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Adam Retail Automation Mobilmen 20t
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-16T12:59:18.926Z

Reserved: 2026-02-12T12:58:51.972Z

Link: CVE-2026-2398

cve-icon Vulnrichment

Updated: 2026-07-10T17:36:59.127Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key